News linked to both this project and an event.
According to The Block, data from blockchain analytics firm Chainalysis shows that violent robberies targeting cryptocurrency holders in the first half of 2026 have resulted in losses exceeding $30 million. If the trend continues in the second half, the full-year total will surpass the historical peak of $58 million in 2025. France has become the world's largest "Wrench Attack" hotspot, with 30 public cases recorded in the first half of 2026, while the French Minister of the Interior stated that actual cases exceed 70. Chainalysis attributes this to the 2024 French tax authority data breach—a tax official was suspected of stealing and selling the names, addresses, holdings, and tax records of high-net-worth crypto holders, causing the attack frequency to surge from a monthly average of 1.9 in 2025 to a monthly average of 4.6 in the first half of 2026. Attack methods have also deteriorated; cases targeting family members rather than the holders themselves now account for over 40% of French cases, and the proportion of home invasions rose from 14% in 2025 to 37%. Stolen funds are typically quickly moved on-chain, with some laundered through tools such as decentralized exchanges and cross-chain bridges; advanced criminal networks are even linked to cartel money laundering and terrorist financing channels.
Odaily News, Chainalysis posted on X platform stating that the Coldcard hack has been particularly devastating for Bitcoin holders in Canada. Our analysis of the attackers and victims found that Canadian BTC holders accounted for 25% of the attributable losses.According to aggregated estimates from Galaxy Research, losses have reached as high as $110 million. We analyzed the geographic distribution of this ongoing hacking campaign. Users in Australia, the United States, and Thailand have also suffered significant losses.
According to Chainalysis, Hexagate detected that the LpdFi protocol suffered an attack of approximately $700,000. The attacker first utilized approximately $44 million in flash loans to artificially inflate the price of LPD tokens on decentralized exchanges to approximately 71 times, subsequently using only approximately $2 million worth of tokens to forge approximately $140 million in deposit positions within the protocol.
Odaily News, January 10 - A Bitcoin and Litecoin holder provided a 12-word recovery phrase to attackers impersonating Trezor support personnel, resulting in the theft of approximately $282 million in assets, including about $139 million in Bitcoin and $153 million in Litecoin. Blockchain forensics firm ZeroShadow stated that the incident stemmed from a social engineering attack, not a compromise of wallet software or private key infrastructure. The stolen funds were split via the THORChain cross-chain bridge within minutes and converted into Monero through instant exchange services. ZeroShadow's monitoring team flagged and froze approximately $700,000 in funds within 20 minutes. Under the BIP39 standard, a 12-word recovery phrase contains approximately 128 bits of entropy, while a 24-word phrase contains 256 bits of entropy. Chainalysis estimates that up to 23% of all mined Bitcoin is permanently inaccessible due to lost keys, involving millions of BTC, with causes including forgotten recovery phrases, damaged backups, and a lack of inheritance planning.
Odaily News, according to Bitcoin News monitoring, Chainalysis analysis of the Coldcard exploit involving over $38 million shows that the attacker deliberately targeted the highest-value wallets first, including one holding $1.8 million, indicating that victims had already been profiled before asset transfers began. Approximately $30 million was stolen in the initial 10 minutes, followed by around 500 wallets being drained within 25 minutes. Block's Clay Garrett stated that investigators also confirmed the attacker used a paid account with a well-known blockchain service provider to query victim addresses during the operation. The provider's internal logs match the request timestamps and sequence, but Block stated that no evidence was found suggesting the company knowingly assisted in the theft. Relevant information has been shared with authorities.
the United States, the European Union, and the United Kingdom have jointly announced sanctions against a group of individuals involved in state-sponsored hacking organizations, cybercriminal groups, and their infrastructure providers. The targets are accused of causing billions of dollars in losses to global enterprises, critical infrastructure, and government agencies. Among them, the most notable is the EU's sanction against Russian cybercriminal Vitaly Nikolayevich Kovalev, also known as "Stern." The EU identified Stern as one of the core managers of the notorious Trickbot Group ransomware syndicate, which is behind high-risk ransomware variants such as Conti ransomware and Ryuk.On-chain analysis shows that wallet addresses linked to Stern have collectively received over $300 million in ransom payments, potentially making him the most prolific ransomware operator ever identified.According to the analysis, the $300 million figure represents only Stern's personal gains, while the total illicit income of the Trickbot Group could be significantly higher. On-chain fund flows indicate that Stern had transactional ties with multiple ransomware ecosystems, including Ryuk, Conti, Diavol, Karakurt, Royal, and Quantum.The investigation reveals that Stern played a role similar to a "CEO" within the Trickbot organization, responsible for budget management, personnel recruitment, infrastructure procurement, and attack planning. (Chainalysis)
leaders of the Group of Seven (G7) issued a statement at the G7 summit in Évian-les-Bains, France, once again calling for joint action to combat North Korean cryptocurrency theft and cybercrime. United Nations security researchers have linked North Korea's cryptocurrency theft to the funding of its weapons programs.Previously, attacks suspected to be linked to North Korean hackers included a $285 million attack on Drift Protocol in April and a $36 million breach on Humanity Protocol in June. According to Chainalysis data, North Korean hackers stole at least $2 billion in cryptocurrency in 2025, bringing their historical total theft amount to at least $6.75 billion. (Cointelegraph)
Odaily Chainalysis posted on X platform, stating that prior to the THORChain theft, wallets suspected to be linked to the attacker had been transferring funds through Monero, Hyperliquid, and THORChain for several consecutive weeks. As early as late April, the attacker-associated wallets deposited funds into Hyperliquid positions via Hyperliquid and the Monero privacy bridge. These funds were subsequently converted to USDC and transferred to Arbitrum, then bridged to Ethereum. Some of the ETH was then moved to THORChain to stake as RUNE for a newly joined node, which is believed to be the source of the attack.Subsequently, the attacker bridged a portion of the RUNE back to Ethereum and split it into four chains. One chain went directly to the attacker, passing through intermediate wallets before transferring 8 ETH to the wallet that would ultimately receive the stolen funds, just 43 minutes before the attack. The funds from the other three chains flowed in reverse. Between May 14 and 15, these wallets bridged the ETH back to Arbitrum again, deposited it into Hyperliquid, and transferred it into Monero via the same privacy bridge, with the final transaction occurring less than 5 hours before the attack commenced. As of Friday afternoon, the stolen funds remain untouched, but the attacker has demonstrated sophisticated cross-chain money laundering capabilities. The Hyperliquid to Monero path may be the next move.